Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-42361 Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoin… Hertzbeat 1.6.0+ Fix from $2,3002024-08-20 CRITICAL 9.8 CVE-2024-43202 Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgr… Dolphinscheduler 3.2.2+ Fix from $2,3002024-08-20 CRITICAL 9.8 CVE-2024-38856 KEVEPSS 99% Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to versi… Ofbiz 18.12.15+ Fix from $2,3002024-08-05 CRITICAL 9.8 CVE-2024-42447 Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used wit… Apache Airflow Providers Fab Patch available Fix from $2,3002024-08-05 CRITICAL 9.8 CVE-2024-36268 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12… Inlong 1.13.0+ Fix from $2,3002024-08-02 CRITICAL 9.1 CVE-2023-48396 Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in an… Seatunnel Mitigation only Fix from $2,3002024-07-30 CRITICAL 9.1 CVE-2024-29070 On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" … Streampark 2.1.4+ Fix from $2,3002024-07-23 CRITICAL 9.1 CVE-2024-29736 A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style att… Cxf 3.5.9 / 3.6.4+ Fix from $2,3002024-07-19 CRITICAL 9.8 CVE-2024-39887 An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certa… Superset 4.0.2+ Fix from $2,3002024-07-16 CRITICAL 9.8 CVE-2024-36522 The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untruste… Wicket 8.16.0 / 9.18.0+ Fix from $2,3002024-07-12 CRITICAL 9.8 CVE-2024-39864 The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integratio… Cloudstack 4.18.2.1 / 4.19.0.2+ Fix from $2,3002024-07-05 CRITICAL 9.8 CVE-2024-38346 The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and … Cloudstack 4.18.2.1 / 4.19.0.2+ Fix from $2,3002024-07-05 CRITICAL 9.8 CVE-2024-38474 Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by th… HTTP Server 2.4.60+ Fix from $2,3002024-07-01 CRITICAL 9.8 CVE-2024-38476EPSS 42% Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend a… HTTP Server 2.4.60+ Fix from $2,3002024-07-01 CRITICAL 9.1 CVE-2024-38475 KEVEPSS 100% Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are p… HTTP Server 2.4.60 / 10.2.1.14-75sv+ Fix from $2,3002024-07-01 CRITICAL 9.1 CVE-2024-29868EPSS 6% Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery … Streampipes after 0.93.0 Fix from $2,3002024-06-24 CRITICAL 9.8 CVE-2024-36265 ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Co… Submarine Mitigation only Fix from $2,3002024-06-12 CRITICAL 9.8 CVE-2024-36264 ** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submari… Submarine Patch available Fix from $2,3002024-06-12 CRITICAL 9.1 CVE-2024-36104EPSS 87% Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before… Ofbiz 18.12.14+ Fix from $2,3002024-06-04 CRITICAL 9.1 CVE-2024-34365 ** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave. A… Karaf Cave Mitigation only Fix from $2,3002024-05-14 CRITICAL 9.8 CVE-2024-32113 KEVEPSS 99% Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before … Ofbiz 18.12.13+ Fix from $2,3002024-05-08 CRITICAL 9.8 CVE-2024-26579 Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0,  the attackers can by… Inlong 1.12.0+ Fix from $2,3002024-05-08 CRITICAL 9.8 CVE-2024-27348 KEVEPSS 99% RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & … Hugegraph 1.3.0+ Fix from $2,3002024-04-22 CRITICAL 9.1 CVE-2024-27349 Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0. User… Hugegraph 1.3.0+ Fix from $2,3002024-04-22 CRITICAL 9.8 CVE-2024-31864 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malic… Zeppelin 0.11.1+ Fix from $2,3002024-04-09 CRITICAL 9.8 CVE-2024-31866 Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding co… Zeppelin 0.11.1+ Fix from $2,3002024-04-09 CRITICAL 9.8 CVE-2024-29006 By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead t… Cloudstack 4.18.1.1+ Fix from $2,3002024-04-04 CRITICAL 9.8 CVE-2024-23538 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer… Fineract 1.9.0+ Fix from $2,3002024-03-29 CRITICAL 9.8 CVE-2024-23539 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer… Fineract 1.9.0+ Fix from $2,3002024-03-29 CRITICAL 9.8 CVE-2024-27438 Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is not checked and may resulting … Doris 2.0.5+ Fix from $2,3002024-03-21